PKI Automation Engineer
Charlotte, NC - USA
Job Summary
Role : PKI Automation Engineer
Location : Chicago IL / Denver CO / Charlotte NC / Dallas TX
Total Positions : # 5
Kind of profiles that we can consider -
- C# Developer PKI Automation
- PowerShell Developer TLS/Certificate Management
- DevOps Engineer Certificate Lifecycle Automation
- PKI Automation Engineer C#/PowerShell )
HM Notes : We are looking for an experienced Certificate Management / PKI Engineer with strong expertise in PKI automation certificate lifecycle management and secure machine identity solutions across enterprise environments. While hands-on experience with Venafi TPP/TLS Protect is preferred candidates without direct Venafi experience will also be considered provided they possess strong PKI engineering fundamentals along with a solid development and automation background using PowerShell or C# to build and streamline certificate provisioning renewal revocation and backend PKI operations. The ideal candidate should have experience with encryption technologies TLS/SSL certificate management API-based automation CI/CD integration Windows/Linux environments and enterprise infrastructure troubleshooting. Exposure to cloud PKI DevOps practices Ansible automation and containerized environments is a plus.
We are seeking an experienced Certificate Management Services Engineer to manage and automate digital certificate lifecycle processes using the Venafi Trust Protection Platform (TPP). The ideal candidate will have deep expertise in PKI certificate automation and secure machine identity management across enterprise environments.
Key Responsibilities
Administer and maintain Venafi TPP processes for certificate provisioning renewal and revocation.
Develop automation solutions using PowerShell or C# to streamline certificate and Venafi /or PKI certification backend operations.
Apply Venafi patches and upgrades including testing and documentation with minimal guidance.
Design and implement automated certificate workflows using Venafi APIs./or any other API
Ensure compliance with security standards and best practices.
Collaborate with DevOps IAM Engineering Deployment and Operations teams to support secure integrations and drive design adoption.
Troubleshoot issues in Windows Server 2022 and RHEL/Unix environments.
Make engineering decisions and implement technical automation solutions.
Operate independently and take initiative in a structured environment.
Required Qualifications
5 years of experience in PKI engineering and certificate lifecycle management.
Strong knowledge of encryption technologies (symmetric/asymmetric cryptography digital signatures certificate authorities).
Proficiency in automation scripting (PowerShell or C#) and clear communication of technical solutions.
Hands-on experience with CI/CD pipelines.
Familiarity with code signing and securing cloud-based applications.
Extensive experience with PKI TLS certificate management and SDLC practices.
Hands-on experience with Venafi TPP TLS Protect or similar certificate management platforms.
Strong understanding of Windows Server RHEL/Linux IIS and networking protocols (TCP/IP DNS HTTP SSH).
Strong troubleshooting skills on Windows platforms.
Experience integrating and automating with Venafi APIs.
Excellent analytical organizational verbal and written communication skills.
Ability to manage multiple priorities in fast-paced environments.
Adaptability to changing requirements and ambiguity.
Ability to influence and align teams to a technical vision.
Self starter with strong motivation and curiosity; able to work with minimal guidance.
Preferred Qualifications
Familiarity with cloud PKI offerings (AWS Azure GCP).
Certifications in PKI Venafi or related security technologies.
Experience in Agile and DevOps environments.
Experience troubleshooting certificate provisioning issues and managing Venafi configurations.
Ability to create/update Ansible Tower/AAP/OpenSource playbooks.
Familiarity with deploying containerized applications.
Bachelors degree in Computer Science Information Security or a related field.